81trust / 100
Email Security
by HALOWERK Agent Tools in Security & trust
x402 APIPassing, checked 4 h ago
Prüft MX, SPF, DKIM, DMARC, MTA-STS, TLS-RPT, BIMI, TLS am Mailserver und DNSSEC einer Domain und leitet daraus Spoofing-Risiko, Punktzahl und Befunde ab. Jeder Befund trägt einen fertigen DNS-Datensatz zum Einfügen statt einer Empfehlung in Prosa. Rein lesend: kein Versand, keine Testmail, keine Relay-Nutzung.
POST https://tools.halowerk.com/v1/email/security
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 40 ms typical, 40 ms slowest 5%
- Last check
- 4 h ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X POST "https://tools.halowerk.com/v1/email/security" \
-H "content-type: application/json" \
-d '{"dkim_selectors":["default","google","selector1"],"domain":"example.com"}'import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Ftools.halowerk.com%2Fv1%2Femail%2Fsecurity
const res = await pay("https://tools.halowerk.com/v1/email/security", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({"dkim_selectors":["default","google","selector1"],"domain":"example.com"}),
});
console.log(await res.json());Example input
{
"dkim_selectors": [
"default",
"google",
"selector1"
],
"domain": "example.com"
}Example output
{
"checked_at": "2026-08-06T12:00:00.000Z",
"checks": {
"dmarc": {
"detail": {
"de": "Kein DMARC-Datensatz.",
"en": "No DMARC record."
},
"status": "fehlt",
"value": {
"record": null
}
},
"spf": {
"detail": {
"de": "SPF endet auf \"~all\" (softfail).",
"en": "SPF ends in \"~all\" (softfail)."
},
"status": "schwach",
"value": {
"all_mechanism": "~all",
"dns_lookups": 4,
"record": "v=spf1 include:_spf.google.com ~all"
}
}
},
"domain": "example.com",
"findings": [
{
"fix": "_dmarc.example.com. 3600 IN TXT \"v=DMARC1; p=none; rua=mailto:[email protected]; adkim=r; aspf=r; pct=100\"",
"severity": "kritisch",
"title": {
"de": "DMARC fehlt",
"en": "DMARC missing"
},
"why_it_matters": {
"de": "Ohne DMARC entscheidet jeder Empfänger selbst, was mit einer gefälschten Mail geschieht.",
"en": "Without DMARC every receiver decides for itself what happens to a forged message."
}
}
],
"score": 41,
"spoofing_risk": "hoch"
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 4 h ago | Passed | 402 | 40 ms | $0.002 |